All privacy policies

Effective and last updated: 2 August 2026

Extension-specific privacy policy

Published by Selfhood Studios

Kuro privacy policy.

This policy applies only to Kuro — Dark Mode for the Future, extension version 1.0.0. Privacy policy version 1.0.0 explains what user data the extension handles, how the data is collected and used, where it is stored, how long it is retained, and every party it may be shared with.

Extension version
1.0.0
Policy version
1.0.0
Selfhood account
Not required
Policy scope
Kuro only
[ 01 ]

Scope

This page is the complete, extension-specific privacy disclosure for Kuro. It does not describe another Selfhood Studios extension. The studio-wide policy remains available at /privacy.

Kuro requires no Selfhood Studios account. Extension data is processed locally unless a feature you deliberately use needs to contact a destination identified in the sharing section below.

[ 02 ]

Prominent disclosure before page data is handled

Kuro analyses page style information locally so it can build a dark theme. Optional remote AI planning is off by default and requires a separate, explicit opt-in before any privacy-filtered page style summary is sent to OpenRouter, DeepSeek, or a custom endpoint you choose.

Handled locally

  • The current page's address, stylesheets, CSS variables, computed colours, semantic element and region types, representative selectors, media counts, and coverage statistics.
  • Theme, palette, contrast, site-rule, profile, schedule, location, circadian, cache, and interface settings.
  • Generated plans, exact-route cache identity, diagnostics, provider configuration, consent state, and the provider token you save.
  • Dynamic-page and tab state needed to keep the correct theme applied as the page changes.

Sent to your AI endpoint

  • Your design vision, selected theme preferences, provider and model choice, and allow-listed privacy-filtered selectors.
  • A compact style summary of colours, variables, semantic region and element types, representative style samples, media counts, contrast findings, and coverage—never page text, form values, screenshots, query strings, fragments, or the raw DOM.
  • The hostname and a parameter-redacted path pattern only when you separately enable Share site identity.
  • Your provider credential where required, plus ordinary connection metadata needed for the direct request.

When a transfer starts: Remote transfer can begin only after you switch site intelligence from Off to Manual or Auto, accept the prominent consent disclosure, and then manually request a plan or allow Auto mode to request one for a page that needs analysis. Turning remote mode off revokes the stored consent grant.

[ 03 ]

Data collected or handled

Kuro handles the address and styling structure of ordinary pages it themes: stylesheet rules and variables; computed background, text, border, and accent colours; semantic element and region types; privacy-filtered representative selectors; media counts; open-shadow-root, frame, stylesheet, and coverage statistics; and the current theme identity and route pattern used to select a cached plan. It also handles the theme, palette, contrast, typography, site-rule, workspace-profile, automation, schedule, user-entered location, circadian-warmth, and interface settings you save; optional custom CSS and development pack overrides; generated local or remote theme plans and their diagnostics; the remote provider, model, design vision, custom endpoint, consent state, and API key or bearer token you choose to configure; and browser tab state needed to apply a theme.

[ 04 ]

How collection occurs

Kuro's declared content scripts match ordinary pages at <all_urls>. A document-start fallback and the selected theme engine read the current page's styles and structure, apply colour transformations, and watch relevant stylesheet, single-page-navigation, open-shadow-root, and dynamic-content changes while Kuro is enabled for that page. Kuro reads tab identifiers and addresses to select per-site settings, exact-route plans, and temporary overrides. Theme preferences, schedules, profiles, provider settings, credentials, and location coordinates come directly from values you enter or controls you change. Local site intelligence samples style facts from the rendered page; it does not need page text, form values, screenshots, query strings, fragments, or the raw DOM in its generated summary. A remote plan is not requested until remote mode is enabled, the required disclosure is accepted, and a manual or automatic planning action calls for it.

[ 05 ]

Permission-by-permission use

These are the Chrome capabilities declared by this extension and the narrow product purpose assigned to each one.

PermissionAccess and purposeWhen used
Host access: <all_urls>Allows Kuro's theme engine and pre-paint fallback to run in ordinary website frames, inspect rendered styles and structure, modify page presentation, and retrieve eligible page-owned stylesheets or images when browser isolation would otherwise block the active engine. Apply the selected dark theme consistently across websites, frames, route changes, shadow roots, and dynamically added content.The lightweight scripts load on matching pages; style inspection and modification run while Kuro is enabled for that site or tab. Chrome-protected pages remain unavailable unless the browser explicitly permits them.
storageStores settings, profiles, site rules, schedules, user-entered coordinates, generated-plan cache entries, consent state, and provider tokens in browser-managed extension storage, with optional browser-native settings sync when you enable it. Remember the theme and privacy choices you configured and replay validated plans without repeated analysis.Used when Kuro loads, saves, imports, exports, resets, synchronises, caches, or deletes the relevant settings or plans.
tabsReads tab identifiers, addresses, active state, navigation changes, and frame state and sends theme updates to the correct open tabs. Select per-site and exact-route rules, maintain temporary tab overrides, update themes after navigation, and show the active site's status.Used while Kuro is enabled, when a page navigates, or when you use a Kuro control. Kuro does not request Chrome's separate browsing-history permission.
scriptingInjects Kuro's disclosed isolated-world engine and pre-paint fallback into eligible tabs that were already open when the extension installed, updated, or restarted. Apply the theme without forcing every existing tab to be manually reloaded.Used as needed for eligible open tabs that do not yet have the current Kuro scripts.
alarmsRuns a local periodic automation check. Activate, deactivate, or change the theme at the configured time, sunrise, sunset, or circadian transition.Used when automation is enabled; the default tick interval is one minute.
offscreenCreates a small extension-owned offscreen document that reads the operating system or browser colour-scheme preference through matchMedia. Support system-theme automation while the background worker has no document context.Used on Chromium when system-theme state is needed; the document is closed when no longer required.
sidePanelDisplays Kuro's Theme, Site, Automation, and Lab console next to the current page. Provide detailed controls and diagnostics without replacing the page you are theming.Used when you open Kuro's side panel through the toolbar or supported browser UI.
contextMenus (optional)Adds Kuro theme controls to the page, frame, image, and link context menus after you grant the optional permission. Offer quick enable, disable, and profile actions from the browser menu.Requested only when you enable context-menu controls and removed again when you disable them.
[ 06 ]

How data is used

Kuro uses this information only to determine whether and how to theme the current page; map colours and enforce the selected contrast and media policies; remember global, profile, site, route, and tab-specific choices; keep dynamic pages themed; activate or change themes according to time, system appearance, sunrise, sunset, and circadian settings; generate, validate, cache, replay, diagnose, and refine privacy-bounded theme plans; fetch page-owned stylesheet or image resources needed by the active engine; and show the toolbar popup, side-panel console, options, shortcuts, and optional context-menu controls. It is not used for advertising, unrelated profiling, eligibility or credit decisions, resale, or data-broker services.

The data is not used for personalized advertising, unrelated profiling, credit or eligibility decisions, resale, or data-broker services.

[ 07 ]

Handling and storage

Settings, site rules, profiles, automation values, user-entered coordinates, provider and model configuration, consent records, generated plan cache entries, installation metadata, and provider tokens are kept in browser-managed extension storage. Provider tokens remain in chrome.storage.local, are excluded from settings export, and are not copied into browser sync. If you explicitly enable Kuro's browser-native settings sync, the settings object—including theme, profile, site, automation, location, and provider-selection fields but not the separately stored provider token—is also written to chrome.storage.sync under your browser account. The default theme-plan cache holds at most 200 entries for at most 90 days; both limits are adjustable. An exact-route replay copy may also live temporarily in that tab and origin's sessionStorage. Tab registry state, automatic-mode state, and temporary tab overrides are session-scoped. Kuro has no Selfhood Studios application backend, account, analytics, advertising, or telemetry service. Locally stored values are not separately encrypted by Kuro; they rely on browser-profile, operating-system, and device security.

Selfhood Studios cannot inspect, recover, or restore data that remains only in your browser profile.

[ 08 ]

All parties data is shared with

Kuro does not send extension data to Selfhood Studios. Local theming and deterministic site planning require no AI provider. Only after you enable Manual or Auto remote planning and explicitly consent does Kuro send a direct request to your selected endpoint: OpenRouter, DeepSeek, or the custom HTTPS endpoint you entered. The recipient receives the provider credential where required, provider and model choice, your design vision and theme preferences, an allow-list of privacy-filtered selectors, and a compact style summary containing colours, CSS-variable samples, semantic region and element types, font size and weight, area ratios, media counts, contrast findings, stylesheet and frame counts, coverage, and complexity. The summary excludes page text, form values, accessible labels, screenshots, query strings, fragments, and the raw DOM. Hostname and a parameter-redacted path pattern are included only if you separately enable Share site identity. The provider also receives ordinary connection metadata such as IP address, request time, and HTTP headers. When an engine must retrieve a cross-origin stylesheet or image already referenced by the page, that resource's origin receives a credential-free, no-referrer request from the browser; private and local network targets are rejected. Selfhood Studios receives information only if you deliberately send it for support or disclosure is legally required. Kuro does not sell or rent data or share it with advertisers or data brokers.

No data is sold or rented, shared with data brokers, or transferred for personalized, retargeted, or interest-based advertising. External recipients process data under their own terms, privacy policies, account settings, and retention controls.

[ 09 ]

Retention and deletion

Theme-plan cache entries expire after the configured age and are least-recently-used trimmed to the configured maximum; the defaults are 90 days and 200 entries. You can clear all cached plans or a site's plan, disable site intelligence, revoke remote-plan or site-identity consent, remove each provider token, reset settings, disable browser-native sync, clear a temporary tab override, or uninstall Kuro. Tab-scoped replay data and temporary state end when the relevant tab or session closes or are cleared when the theme or plan no longer applies. Other local or browser-synced settings remain until you change, reset, or delete them or uninstall the extension, subject to the browser account's own sync behaviour. A request already sent to OpenRouter, DeepSeek, or a custom endpoint follows that recipient's logs, account settings, contract, and retention policy; Selfhood Studios cannot retrieve or delete that copy.

Before uninstalling, use the extension's delete, clear, reset, or export controls where available. Uninstalling normally removes browser-managed extension storage from that Chrome profile.

[ 10 ]

Your privacy controls

You control whether optional remote processing is configured and can reduce, remove, or avoid the data handled by the extension:

  • Keep remote planning Off to use Kuro's deterministic local planning and all four rendering engines without sending a style summary to an AI provider.
  • Choose Manual instead of Auto so a remote request occurs only when you explicitly generate a plan for the current site.
  • Keep Share site identity off to withhold the hostname and redacted path pattern even when remote planning is enabled.
  • Turn remote planning off to revoke consent, remove provider tokens individually, change the provider, model, design vision, or custom endpoint, and review the provider's policy before enabling remote processing.
  • Disable Kuro globally or for a site, use a temporary tab override, clear one site's plan or the entire plan cache, adjust cache age and size, reset settings, or uninstall Kuro.
  • Leave browser-native settings sync and optional context-menu controls disabled unless you want those features; provider tokens are never included in settings sync or export.
[ 11 ]

What the extension does not collect or do

  • Kuro does not create a Selfhood Studios account or send page information, theme settings, credentials, site rules, or generated plans to a Selfhood Studios backend.
  • Kuro does not include Selfhood analytics, advertising, telemetry, session replay, or cross-site tracking; its telemetry setting is fixed off in the current product.
  • Remote style summaries do not contain page text, form values, accessible labels, screenshots, query strings, URL fragments, or the raw DOM.
  • Kuro does not request Chrome's browsing-history permission or read a blanket list of previously visited pages.
  • Kuro does not sell data, share it with data brokers, or use it for personalised advertising, eligibility decisions, or unrelated profiling.
[ 12 ]

Security

Remote requests containing user data or credentials use secure transport such as HTTPS or WSS, except a user-configured service that is deliberately hosted on the same device or private network. Authentication information is not publicly disclosed.

Local data relies on Chrome's extension isolation and the security of your Chrome profile, operating system, and device. No security measure is absolute; protect your device account and revoke a provider credential if you believe it has been exposed.

[ 13 ]

Chrome Web Store Limited Use disclosure

User data is used only to provide or improve Kuro's disclosed single purpose and user-facing features. Selfhood Studios does not permit personnel or contractors to read extension data. Routine human access is not possible because Selfhood Studios does not receive extension content.

The limited exceptions are when you explicitly send specific data for support, access is necessary to investigate security or abuse, disclosure is required by law, or data is first aggregated and anonymized for lawful internal operations.

The use of information received from Google APIs will adhere to the Chrome Web Store User Data Policy, including the Limited Use requirements.

[ 14 ]

Notice, choices, and contact

Where a feature sends data to a third party, the transfer must be disclosed before it begins and occur only after an affirmative user action. You can avoid the transfer by not invoking or enabling that optional feature, and you can remove local data through the controls described above.

Analytics on this marketing website are separate from the extension and cannot access its stored content. Website practices are explained in the studio-wide privacy policy.

For a privacy question, rights request, or security report, contact Selfhood Studios. Do not send API keys or unrelated private content.